CFAIL 2026 Paper: Unintended Features of APIs: The OpenSSL Bug That Quietly Disappeared

The paper “Unintended Features of APIs: The OpenSSL Bug That Quietly Disappeared” was accepted at CFAIL 2026. This is the eighth edition of the Conference for Failed Approaches and Insightful Losses in Cryptology, an affiliated event of Crypto 2026.

This paper follows up on Benmocha et al.’s “Unintended Features of APIs: Cryptanalysis of Incremental HMAC” (SAC 2020), which describes a vulnerability in the HMAC implementations of several cryptographic libraries, including OpenSSL. The CFAIL paper explains how this vulnerability was unintentionally resolved due to an unrelated hardware-token compatibility fix. It is a detailed case study that provides insights into the development of cryptographic APIs.

It is a single-author paper by Nicky Mouha, Founder of KeyCryptic.